Dolomite Hack
What happened
Dolomite's deprecated Ethereum legacy product was exploited for about $1.8 million through lingering approvals to an old Loopring Trade Delegate and an invalid-order signature-validation bypass. The legacy system had been spun down in 2020; this was not an attack on Dolomite's current deployment. Dolomite recovered 90% of affected assets and used treasury funds to reimburse every victim.
The legacy Loopring and Dolomite architecture relied on downstream order validation to revert. Defensive and gas-optimization handling allowed malformed orders to continue, while a partially-filled-order state bypassed signature verification. Lingering user approvals supplied the authority for the drain.
Case & protocol details
How it happened
The exploiter submitted invalid orders together with two valid orders. The invalid orders initiated victim margin deposits through SoloMargin, then a crafted state caused Loopring's OrderHelper to skip signature verification for partially filled orders. The valid ring exchanged approved victim assets for tiny LRC amounts.
The vulnerable legacy Trade Delegate was disabled within an hour. Dolomite recovered 90% of assets and made up the remaining 10% from treasury, completing victim reimbursements on March 26.
Funds Recovery
Recovered
$1.8M
Net Loss
$0
Evidence & learning
Sources and on-chain records
- report Report cryptotimes.io
- report Dolomite Legacy Smart-Contract Vulnerability Post-Mortem zeroshadow.io
- transaction Dolomite DAI Reimbursement Transaction etherscan.io
- transaction Dolomite WETH Reimbursement Transaction etherscan.io
- transaction Dolomite USDC Reimbursement Transaction etherscan.io
- analysis Website reference twitter.com
- analysis Dolomite Approval-Drain Incident revoke.cash
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.